That page doesn't exist. Search or drop a file below to find the tool you need.
What do you need to get done?
- Stays on this device
- No watermark
- Works offline
Drop a file here
or .
Open an app
Follow a recipe
Use one tool
JWT encoder
Create a signed JSON Web Token for testing. Edit the header and payload, pick an algorithm from HS256 to ES512, enter a secret or a private key and copy the token. It is signed in your browser, so your key is never uploaded.
How to create a JWT
- 1Choose the algorithm, for example HS256 or RS256
- 2Edit the payload and enter the secret or private key
- 3Copy the token, or open it in the decoder
- A signed JWT you can use for tests.
What you get
- Twelve algorithms.HS, RS, PS and ES, each with 256, 384 or 512 bits.
- Signed in your browser.Your secret or private key is used on your device and never sent.
- A token that is really valid.Your own verifier accepts it. Use test keys only.
What you can do
- Sign with HS256, HS384 or HS512 using a shared secret.
- Sign with RS256/384/512, PS256/384/512 or ES256/384/512 using a private key in PKCS#8 PEM or JWK form.
- Edit the header and payload as JSON. The payload starts with sub, name, iat and an exp one hour ahead.
- Update the token as you type, and keep the header's alg in step with the algorithm you choose.
- Open the new token in the decoder with "Decode it" to check it.
Good to know
- Tokens signed here are real. Use test keys, never a key that protects a live system.
- For HS256 use a secret of at least 32 characters. Shorter ones work, but the tool reminds you that they are only fine for tests.
- Private keys must be PKCS#8 (-----BEGIN PRIVATE KEY-----). An older RSA or EC key needs converting first with openssl pkcs8 -topk8 -nocrypt.
- iat and exp are plain numbers in seconds. Change them by hand, or use the Unix timestamp converter to find a value.
Questions
How do I create a JWT for testing?
Pick an algorithm, edit the payload, enter a secret (for HS) or a private key, and copy the token that appears.
Which algorithms can I sign with?
HS256, HS384, HS512, RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384 and ES512.
Is my secret or private key uploaded?
No. The signing uses your browser's own crypto functions on your device. Nothing is sent anywhere.
Can I use the token in production?
Not with a key from here. Anything you paste into a web page should be a test key. For real systems, sign tokens on your server.